StudyToCert

All certifications / AZ-802 / Lessons

Microsoft Certified: Windows Server Administrator Associate (exam AZ-802: Administering Windows Server) AZ-802 · Domain 1: Deploy and manage AD DS

Default Domain Policy vs fine-grained password policies (PSOs); AD Recycle Bin

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Every domain needs a password and account lockout policy for its user accounts. For domain accounts, that policy comes from Group Policy settings under Computer Configuration, Policies, Windows Settings, Security Settings, Account Policies, and it only takes effect when the GPO is linked at the domain level. By convention it lives in the Default Domain Policy. If you link a GPO with password settings to an OU, it affects only the local accounts on computers in that OU, not domain users. That is the classic limitation: one password policy per domain.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 6 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study AZ-802 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the AZ-802 study plan